tcpdump is a common packet analyzer that runs under the command line. It allows the user to intercept and display TCP/IP and other packets being transmitted or received over a network to which the computer is attached.



Wireshark is described as 'Foremost network protocol analyzer with multi-platform support, deep protocol inspection, VoIP analysis, and extensive file format compatibility' and is a leading network analyzer in the network & admin category. There are more than 50 alternatives to Wireshark for a variety of platforms, including Windows, Linux, Mac, Android and iPhone apps. The best Wireshark alternative is tcpdump, which is both free and Open Source. Other great apps like Wireshark are CloudShark, Intercepter-NG, NetworkMiner and Proxyman.
tcpdump is a common packet analyzer that runs under the command line. It allows the user to intercept and display TCP/IP and other packets being transmitted or received over a network to which the computer is attached.



Optimize packet capture workflow with CloudShark's secure, collaborative network analysis. It's ideal for IT teams and operators, available on any device. Share and solve problems faster with browser-based collaboration and centralized PCAP data management on-premise or in the cloud.
Intercepter-NG is a multifunctional network toolkit for various types of IT specialists.



NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can extract transmitted files and certificates from PCAP files containing HTTP, FTP, SMB, SMB2, TFTP and several other protocols.




Proxyman is a high-performance macOS app, which enables developers to view HTTP/HTTPS requests from apps and domains. Available on macOS, iOS, Windows & Linux.




Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks.

PCAPdroid is an android app to capture the phone traffic and analyze it remotely (e.g. via Wireshark). The traffic can be easily downloaded from a remote device thanks to the integrated HTTP server, or streamed to a remote UDP receiver.




Capsa performs real-time packet capturing, 24/7 network monitoring, protocol analysis, in-depth packet decoding, and automatic expert diagnosis.






MicroOLAP TCPDUMP is a clone of tcpdump , the most used network sniffer/analyzer for UNIX, compiled with the original tcpdump code (http://www.tcpdump.org/), and MicroOLAP Packet Sniffer SDK.

Sysdig is open source, system-level exploration: capture system state and activity from a running Linux instance, then save, filter and analyze. Think of it as strace + tcpdump + lsof + awesome sauce.
It's open source and use CLI